- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: 2 VPN tunnels with 2 different IP address
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 VPN tunnels with 2 different IP address
Hi guys.
We have a question regarding the creation of a second tunnel and the link selection configuration.
We wanted to configure one of the external interfaces of the firewall that has another public IP to set up another VPN tunnel against a site.
We saw the following technical note
We currently have all the tunnels based on domain based encryption policies against the IP defined in the firewall by link selection, would this change imply a change or type of outage in the tunnels currently set up against that IP?
We welcome your comments.
Thank you
- Labels:
-
Quantum
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the actual Link Selection configuration currently?
I suspect for this to work, you'll need to do it based on the routing table.
R82 has much better Link Selection settings (can be set per VPN community).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Phoneboy!
Currently the link selection in the firewall is configured as follows:
Always use this IP address --> Selected address from topology table --> IP address
The IP address that we currently want to use would be a different public IP than the one that is currently configured in this way. We currently have R81.20 installed on the firewalls that are VS from SGM master.
Thank you for your comments.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You'd have to change to "Calculate IP Based on Network Topology" and also set the Outgoing Route Selection accordingly.
Like I said, you can set different Link Selection per community in R82.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I will double check this in my lab (R82 one as well), but I believe link selection probing method would also work here.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would only perform this type of changes in a small maintenance window.
You might also need to change this:
https://support.checkpoint.com/results/sk/sk160672
During window make sure new VPN tunnel works, but also old tunnels! Consider even to reset them with vpn tu during window to make sure that re-key part is
This type of config is a bit trial / error so better do it in a window
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Checkpointer.
Thanks for sharing your lab, it looks very interesting for our purpose.
You used the Calculate IP Based on Network Topology configuration and then the Operating system routing table, using the VPN by policies without problems, correct?
Thank you very much for the info.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes, that's correct
please test on maintnance window
